---
id: "nsec-nsec3"
kind: "glossary-term"
title: "NSEC and NSEC3"
language: "en"
category: "DNS and technical foundations"
updated: "2026-10-04T14:01:23Z"
canonical: "https://tldlog.com/glossary/nsec-nsec3/"
translations:
  es: "https://tldlog.com/es/glosario/nsec-nsec3/"
  de: "https://tldlog.com/de/glossar/nsec-nsec3/"
  fr: "https://tldlog.com/fr/glossaire/nsec-nsec3/"
  it: "https://tldlog.com/it/glossario/nsec-nsec3/"
  pt-BR: "https://tldlog.com/pt/glossario/nsec-nsec3/"
  ru: "https://tldlog.com/ru/glossariy/nsec-nsec3/"
  zh-Hans: "https://tldlog.com/zh/cihui/nsec-nsec3/"
---

# NSEC and NSEC3

Next Secure and Next Secure version 3

DNSSEC records that prove a name or record type does not exist, so that a 'no such name' answer cannot be faked. NSEC lists the next existing name in the zone, which lets anyone list all names. NSEC3 uses scrambled versions of the names to make that harder.

## related terms

- [DNSSEC](https://tldlog.com/glossary/dnssec/)
- [NXDOMAIN](https://tldlog.com/glossary/nxdomain/)
- [RRSIG](https://tldlog.com/glossary/rrsig/)
- [zone signing](https://tldlog.com/glossary/zone-signing/)
- [zone file](https://tldlog.com/glossary/zone-file/)
